Description
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
Remediation
References
Related Vulnerabilities
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (3.1.3)
Moodle Improper Input Validation Vulnerability (CVE-2022-35649)
Microsoft SQL Server Other Vulnerability (CVE-2000-0202)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-7848)
MediaWiki Use of Hard-coded Credentials Vulnerability (CVE-2012-4381)